在 Matthias-Wandel 的 jhead 版本 3.3 及更早版本中发现了一个弱点。该问题影响 EXIF 解析组件中 exif.c 文件里的 Get16u 函数。这一操作会导致越界读取(out-of-bounds read)。此漏洞利用本地访问权限即可触发。利用该漏洞的攻击方法已向公众公开,可被用于发动攻击。项目方早已通过问题报告获知此问题,但至今尚未做出回应。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Matthias-Wandel | jhead | 3.0 |
cpe:2.3:a:matthias-wandel:jhead:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet